Attackers Are Exploiting a Maximum-Severity Cisco ISE Flaw
Want more insights like this?
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading